cbcvebase.
CVE-2023-43472
published 2023-12-05

CVE-2023-43472: An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.

PriorityP267high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EXPLOIT
EPSS
36.58%
98.4th percentile
An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.

Affected

2 ranges
VendorProductVersion rangeFixed in
lfprojectsmlflow<= 2.8.1—
lfprojectsmlflow>= 0 < 2.9.02.9.0

Detection & IOCsextracted from sources · hover to see the quote

url/api/2.0/preview/mlflow/experiments/list↗
  • →Shodan query 'http.title:"mlflow"' can be used to identify exposed MLflow instances potentially vulnerable to CVE-2023-43472. ↗
  • →FOFA query 'app="MLflow"' can be used to identify exposed MLflow instances potentially vulnerable to CVE-2023-43472. ↗
  • ·The vulnerability affects MLflow versions 2.8.1 and before; the unauthenticated REST API endpoint is accessible without credentials, indicating no authentication is enforced on this endpoint in affected versions. ↗
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.